Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2022-32227
A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "v…
Rocket.chat
4.7.5 / 4.8.2+
MEDIUM 5.9
CVE-2022-38846
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attack…
Espocrm
No fix yet
MEDIUM 6.5
CVE-2022-30312
The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Tre…
Trend Iq412 Firmware
Mitigation only
HIGH 7.5
CVE-2022-2083
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access …
Simple Sign On
after 4.1.0
CRITICAL 9.1
CVE-2022-2003
AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with th…
D0 06dd1 Firmware
2.72+
HIGH 7.5
CVE-2022-2005
AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker…
C More Ea9 T6cl Firmware
6.73+
HIGH 7.5
CVE-2022-2485
Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in t…
Sio Mb04rtds Firmware
8.0.4.0 / 8.3.4.0+
HIGH 7.5
CVE-2022-36200
In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.
Hg150 Ub Firmware
No fix yet
HIGH 8.8
CVE-2021-3590
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output…
Satellite
Mitigation only
MEDIUM 5.3
CVE-2022-2338
Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration int…
Edgeaggregator
Mitigation only
HIGH 8.2
CVE-2022-32245
SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive info…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 5.9
CVE-2022-27619
Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows ma…
Note Station
2.2.2-609+
HIGH 7.5
CVE-2022-31204
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or …
Sysmac Cs1 Firmware
1.5 / 1.10+
MEDIUM 5.9
CVE-2022-28861
The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to see FTP credenti…
Citilog
Mitigation only
MEDIUM 6.5
CVE-2017-20109
A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the fi…
Teleopti Workforce Management
after 7.1.0
HIGH 7.5
CVE-2022-29519
Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an …
Stardom Fcj Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-21829
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead…
Concrete Cms
8.5.8 / 9.1.0+
MEDIUM 5.9
CVE-2022-1524
LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials.
Local Run Manager
after 3.1
MEDIUM 5.9
CVE-2022-21184
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaint…
Atvise
Mitigation only
MEDIUM 6.5
CVE-2022-25805
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind credentials by the cmd_mgt_loa…
Universal Management Suite
No fix yet
MEDIUM 5.9
CVE-2022-29733
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerab…
Entelitouch Firmware
No fix yet
MEDIUM 6.1
CVE-2021-28508
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig trans…
Terminattr
1.10.11 / 1.16.8+
MEDIUM 6.1
CVE-2021-28509
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig trans…
Terminattr
1.10.11 / 1.16.8+
HIGH 7.5
CVE-2022-26077
A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automatio…
Oas Platform
No fix yet
HIGH 7.5
CVE-2021-32966
Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive info…
Interoperability Solution Xds
after 2021-1
MEDIUM 6.8
CVE-2022-21951
A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network d…
Rancher
2.5.14 / 2.6.5+
HIGH 8.8
CVE-2022-29874
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicate in cle…
7kg8500 0aa00 0aa0 Firmware
3.00+
HIGH 7.5
CVE-2021-32934
The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not using AuthKey for IOTC conne…
Kalay P2p Software Development Kit
after 3.1.5
MEDIUM 5.9
CVE-2020-4970
IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by th…
Security Identity Manager
Mitigation only
HIGH 7.5
CVE-2022-30993
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
Cyber Protect
15+